summaryrefslogtreecommitdiffstats
path: root/hw/core/sysbus.c
diff options
context:
space:
mode:
authorPhilippe Mathieu-Daudé2020-08-06 15:09:45 +0200
committerLaurent Vivier2020-09-01 09:28:28 +0200
commitf234501c67234d54dc75f34eb76988c929778070 (patch)
tree882c2b1c63ce38cf157063edf26798bc9145341f /hw/core/sysbus.c
parenthw/core/sysbus: Fix a typo (diff)
downloadqemu-f234501c67234d54dc75f34eb76988c929778070.tar.gz
qemu-f234501c67234d54dc75f34eb76988c929778070.tar.xz
qemu-f234501c67234d54dc75f34eb76988c929778070.zip
hw/core/sysbus: Assert memory region index is in range
Devices incorrectly modelled might use invalid index while calling sysbus_mmio_get_region(), leading to OOB access. Help developers by asserting the index is in range. Signed-off-by: Philippe Mathieu-Daudé <f4bug@amsat.org> Reviewed-by: Richard Henderson <richard.henderson@linaro.org> Message-Id: <20200806130945.21629-3-f4bug@amsat.org> Signed-off-by: Laurent Vivier <laurent@vivier.eu>
Diffstat (limited to 'hw/core/sysbus.c')
-rw-r--r--hw/core/sysbus.c1
1 files changed, 1 insertions, 0 deletions
diff --git a/hw/core/sysbus.c b/hw/core/sysbus.c
index 77ab351ce1..294f90b7de 100644
--- a/hw/core/sysbus.c
+++ b/hw/core/sysbus.c
@@ -199,6 +199,7 @@ void sysbus_init_mmio(SysBusDevice *dev, MemoryRegion *memory)
MemoryRegion *sysbus_mmio_get_region(SysBusDevice *dev, int n)
{
+ assert(n >= 0 && n < QDEV_MAX_MMIO);
return dev->mmio[n].memory;
}